Heap out-of-bounds write in Linux kernel - CVE-2018-5332
Published: January 11, 2018 / Updated: January 12, 2018
Vulnerability identifier: #VU10002
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5332
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists in the rds_message_alloc_sgs() function due to improper validation of DMA page allocation values. A local attacker can trigger a heap-based out-of-bounds write and cause the system to crash.
The weakness exists in the rds_message_alloc_sgs() function due to improper validation of DMA page allocation values. A local attacker can trigger a heap-based out-of-bounds write and cause the system to crash.
Affected software
Linux kernel
Debian Linux
SUSE Linux
Fedora
MRG Realtime
kernel
Debian Linux
SUSE Linux
Fedora
MRG Realtime
kernel
How to mitigate CVE-2018-5332
Install update from vendor's website.
kernel - addressed in versions 4.14.14-200.fc26, 4.14.14-300.fc27
External References
Related Security Bulletins
- Multiple vulnerabilities in Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- Debian update for linux
- Red Hat update for Red Hat Enterprise MRG Realtime 2.5
- Fedora 27 update for kernel
- Fedora 26 update for kernel